First published: Thu Jun 15 2023(Updated: )
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker could redirect a user to any URL if url sanitisation is bypassed in incoming requests. NOTE: this is similar, but not identical, to CVE-2021-34807.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | =8.8.15 | |
Zimbra Collaboration Suite | =8.8.15-p1 | |
Zimbra Collaboration Suite | =8.8.15-p10 | |
Zimbra Collaboration Suite | =8.8.15-p11 | |
Zimbra Collaboration Suite | =8.8.15-p12 | |
Zimbra Collaboration Suite | =8.8.15-p13 | |
Zimbra Collaboration Suite | =8.8.15-p14 | |
Zimbra Collaboration Suite | =8.8.15-p15 | |
Zimbra Collaboration Suite | =8.8.15-p16 | |
Zimbra Collaboration Suite | =8.8.15-p17 | |
Zimbra Collaboration Suite | =8.8.15-p18 | |
Zimbra Collaboration Suite | =8.8.15-p19 | |
Zimbra Collaboration Suite | =8.8.15-p2 | |
Zimbra Collaboration Suite | =8.8.15-p20 | |
Zimbra Collaboration Suite | =8.8.15-p21 | |
Zimbra Collaboration Suite | =8.8.15-p22 | |
Zimbra Collaboration Suite | =8.8.15-p23 | |
Zimbra Collaboration Suite | =8.8.15-p24 | |
Zimbra Collaboration Suite | =8.8.15-p25 | |
Zimbra Collaboration Suite | =8.8.15-p26 | |
Zimbra Collaboration Suite | =8.8.15-p27 | |
Zimbra Collaboration Suite | =8.8.15-p28 | |
Zimbra Collaboration Suite | =8.8.15-p29 | |
Zimbra Collaboration Suite | =8.8.15-p3 | |
Zimbra Collaboration Suite | =8.8.15-p30 | |
Zimbra Collaboration Suite | =8.8.15-p31 | |
Zimbra Collaboration Suite | =8.8.15-p32 | |
Zimbra Collaboration Suite | =8.8.15-p33 | |
Zimbra Collaboration Suite | =8.8.15-p34 | |
Zimbra Collaboration Suite | =8.8.15-p4 | |
Zimbra Collaboration Suite | =8.8.15-p5 | |
Zimbra Collaboration Suite | =8.8.15-p6 | |
Zimbra Collaboration Suite | =8.8.15-p7 | |
Zimbra Collaboration Suite | =8.8.15-p8 | |
Zimbra Collaboration Suite | =8.8.15-p9 | |
Zimbra Collaboration Suite | =9.0.0 | |
Zimbra Collaboration Suite | =9.0.0-p0 | |
Zimbra Collaboration Suite | =9.0.0-p1 | |
Zimbra Collaboration Suite | =9.0.0-p10 | |
Zimbra Collaboration Suite | =9.0.0-p11 | |
Zimbra Collaboration Suite | =9.0.0-p12 | |
Zimbra Collaboration Suite | =9.0.0-p13 | |
Zimbra Collaboration Suite | =9.0.0-p14 | |
Zimbra Collaboration Suite | =9.0.0-p15 | |
Zimbra Collaboration Suite | =9.0.0-p19 | |
Zimbra Collaboration Suite | =9.0.0-p2 | |
Zimbra Collaboration Suite | =9.0.0-p23 | |
Zimbra Collaboration Suite | =9.0.0-p25 | |
Zimbra Collaboration Suite | =9.0.0-p26 | |
Zimbra Collaboration Suite | =9.0.0-p27 | |
Zimbra Collaboration Suite | =9.0.0-p3 | |
Zimbra Collaboration Suite | =9.0.0-p4 | |
Zimbra Collaboration Suite | =9.0.0-p5 | |
Zimbra Collaboration Suite | =9.0.0-p6 | |
Zimbra Collaboration Suite | =9.0.0-p7 | |
Zimbra Collaboration Suite | =9.0.0-p7.1 | |
Zimbra Collaboration Suite | =9.0.0-p8 | |
Zimbra Collaboration Suite | =9.0.0-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24030 is classified as a moderate severity vulnerability due to its potential for exploitation based on valid authentication tokens.
To address CVE-2023-24030, ensure you are using the latest version of Zimbra Collaboration Suite and apply any security patches released by Zimbra.
CVE-2023-24030 affects Zimbra Collaboration Suite versions up to 9.0 and 8.8.15, including various patches of those versions.
CVE-2023-24030 can be exploited through open redirection after an attacker has obtained a valid Zimbra authentication or preauth token.
The risks of CVE-2023-24030 include potential phishing attacks and the unauthorized redirecting of users to malicious sites.